Unrated severityNVD Advisory· Published Aug 26, 2010· Updated Apr 29, 2026
CVE-2009-3743
CVE-2009-3743
Description
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.
Affected products
31cpe:2.3:a:artifex:afpl_ghostscript:6.0:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:artifex:afpl_ghostscript:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:6.01:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:6.50:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:7.00:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:7.03:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:7.04:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.00:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.11:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.12:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.13:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.14:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.50:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.51:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.52:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.53:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:afpl_ghostscript:8.54:*:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript_fonts:6.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:artifex:ghostscript_fonts:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:ghostscript_fonts:8.11:*:*:*:*:*:*:*
cpe:2.3:a:artifex:gpl_ghostscript:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:artifex:gpl_ghostscript:*:*:*:*:*:*:*:*range: <=8.70
- cpe:2.3:a:artifex:gpl_ghostscript:8.01:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.15:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.50:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.51:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.54:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.56:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.57:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.60:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.61:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.62:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.63:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:gpl_ghostscript:8.64:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.kb.cert.org/vuls/id/644319nvdUS Government Resource
- www.kb.cert.org/vuls/id/JALR-87YGN8nvdUS Government Resource
- security.gentoo.org/glsa/glsa-201412-17.xmlnvd
- www.securityfocus.com/archive/1/514892/100/0/threadednvd
- www.securitytracker.com/idnvd
- rhn.redhat.com/errata/RHSA-2012-0095.htmlnvd
News mentions
0No linked articles in our index yet.